English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22222
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Plug and Play À¥ ¼­¹ö´Â dot dot ½ÃÄö½º¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Plug and Play À¥ ¼­¹ö´Â Windows Ç÷§Æû »ó¿¡¼­ À¥ »çÀÌÆ®¸¦ ±¸ÃàÇϱâ À§ÇÑ ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÌ´Ù. ÀÌ À¥ ¼­¹öÀÇ 1.0002c ¹öÀü¿¡´Â '../' ¶Ç´Â '..\' ½ÃÄö½º¸¦ »ç¿ëÇÏ¿© ¼­¹öÀÇ ·çÆ® µð·ºÅ丮 ¿ÜºÎ¸¦ Ž»öÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ À¥ ¼­¹ö¿¡ '../' ¶Ç´Â '..\' ½ÃÄö½º¸¦ »ç¿ëÇÏ¿© Àß Á¶ÀÛµÈ URL ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, ´ë»ó ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇϸé Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖÀ¸¸ç, ȹµæµÈ Á¤º¸µéÀº ´ë»ó ½Ã½ºÅÛ¿¡ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇϱâ À§ÇØ À¯¿ëÇÏ°Ô »ç¿ëµÉ ¼ö ÀÖ´Ù.

http://[target_server]/../../windows/win.ini

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/338090

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Plug and Play Web Server 1.0 002c
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 8645 (SecurityFocus)
°ü·Ã URL (ISS)